
CyberWire Daily Million-dollar hacks and a manhunt.
Jan 20, 2026
Tim Starks, a Senior Reporter at CyberScoop, dives into crucial cybersecurity issues. He discusses the manhunt for the Black Basta ransomware group and a new UK initiative to combat fraud. The conversation highlights an alarming LinkedIn phishing campaign using malicious tools and a data breach affecting over 42,000 people at Ingram Micro. Tim also explains the surprises and challenges surrounding Sean Plankey's renomination to lead CISA, underscoring the complex political landscape impacting his confirmation.
AI Snips
Chapters
Transcript
Episode notes
Black Basta's Global Reach
- Black Basta has operated since at least 2022 and extorted hundreds of organizations worldwide.
- Investigations link its structure to Conti and Ryuk and suggest large-scale financial impact.
Centralize Fraud Reporting
- Use centralized reporting and real-time analytics to improve fraud investigations.
- Report Fraud promises follow-up updates and better coordination with telecoms and tech firms to disrupt criminals.
Social Platforms As Attack Vectors
- LinkedIn DMs are being weaponized with staged WinRAR archives and DLL sideloading to evade detection.
- Attackers leverage open-source pentest tools for persistence, lateral movement, and data theft.

